Match plus provenance
KYC Data Provenance Review
A match is not proof of a person.
Provero helps KYC, IDV and fraud teams identify breached, recycled, synthetic and low-trust records before they become trusted evidence in downstream workflows. A database match proves records line up. It does not prove the record is fresh, consented, independent, or safe to trust.
To request a data provenance review, email support@provero.io
What Provero checks
Breach exposure across email, phone, IP, username, domain and password signals
Dead, unreachable or inconsistent phone numbers
IP fraud signals including proxies, VPNs, TOR, bots and abuse history
IP and location mismatches against the claimed identity
Impossible dates, invalid chronology and generated-looking fields
Source-level patterns across suppliers, campaigns and inbound data feeds
Why a match is not proof
A KYC match proves that two records line up. It does not prove that a real, consenting person is behind them. The same identity spine, name, address, postcode and date of birth, can carry completely different origin stories, and the match cannot tell you which one it is confirming.
The same stolen record arriving by many routes looks like corroboration, but it is redistribution. Once a record enters the data ecosystem it is sold, enriched and re-permissioned, so when it later appears in several places, that is often one origin arriving by several routes, not several independent witnesses.
Standard spine-only checks are blind to this by construction. Breach and fraud signals often live in the email, phone, IP, username and password data, which the spine does not include. A clean, compliant match can therefore confirm a breached or recycled record without ever surfacing a risk signal.
A match proves alignment. Provenance helps decide whether that alignment should be trusted.
Read the full argument: why a match is not proof of a person →
What a data provenance review reveals
A data provenance review reads the tells a spine-only check cannot see. These are examples, drawn from our own anonymised analysis, of the kinds of thing that are catchable, not a how-to.
Extreme breach concentration on a source
A single source running breach exposure above 90%, where a genuinely current, trusted feed sits around 40 to 50%.
Unusually old breach ages
Breaches averaging around nine years old, against around three years in clean data. Recent exposure is ordinary; very old exposure at scale is not.
Impossible chronology
People who appear not to have been born when their data was first breached, which cannot happen for a real human record.
Calendar dates that cannot exist
Date fields such as 30 February or 31 April. Nothing produces those except a generator inventing data.
Dead numbers that are breach-exposed
Phone numbers that are dead yet sit in a known breach, which is strange for supposedly fresh, recently collected traffic.
Inconsistent location signals
IP or location signals that do not line up with the claimed identity.
Synthetic-looking repetition or generated patterns
Fields that repeat or vary in machine-like ways, a sign of records assembled or generated rather than collected from real people.
Each tell is a pattern-level signal, not proof about any single person. A breach rate is a floor, not a ceiling, because it only counts breaches that have been reported and indexed, so the real figure is never lower than the one you see.
Two ways to use Provero
Request a data provenance review
Send us a sample of inbound data, supplier data or existing records. We examine it for breach, chronology, phone, fraud, location and synthetic-pattern signals, then report what we found so you can decide what to trust, challenge, suppress or review.
To request a review, email support@provero.io
Run the checks yourself
Use the APIs or bulk upload to run the same signals directly in your own workflow, on every record as it arrives or across an existing dataset.
See the checks you can run →Run the provenance and fraud signals yourself
Each API returns an individual signal. The value comes from reading the pattern across them, manually, in a review, or in a single call with Multi-Validation. These run today as a real-time API or a bulk upload.
Breach Detection API
from £0.012Know if an identity is already exposed, check emails, phones, IPs, usernames, domains and passwords against known breach data.
Explore Breach Detection →HLR Phone Verification API
from £0.0042Confirm a number is a real mobile and see the network actually serving it now, not just that the number is correctly formatted.
Explore HLR Phone Verification →Email Verification API
from £0.006Reach inboxes, not bounces, confirm an address is deliverable before you send.
Explore Email Verification →IP Fraud Detection API
from £0.02Spot the fraud before it gets in, proxies, VPNs, TOR, bots and abuse history in a single 0–100 score.
Explore IP Fraud Detection →IP Geolocation API
from £0.008Check they are where they say they are, resolve an IP and match it to the address they gave you.
Explore IP Geolocation →Name Validation API
FreeCatch fake and junk names, flag profanity, gibberish and obviously fake names before they reach your CRM.
Explore Name Validation →Multi-Validation API
you pay the per-request rate for each check included in the callRun every check you need in one request and get each check's result back together: one call, every signal.
Explore Multi-Validation →Where we are heading
We are building towards a single provenance-weighted outcome score that combines these signals automatically, so you read one number instead of assembling the pattern from individual checks yourself.
Today, you can run the individual checks directly or ask us to review the patterns for you. The score is not shipping yet; early accounts will get first access to it as it lands.
What early users say
"We tested Provero as an additional layer for our KYC data provenance due diligence and the outcome reports were very insightful. We could identify data that was part of a legacy breach, data that existed on national suppression files along with detailed phone and email validation flags. Really impressive solution and would recommend to anyone onboarding new data or to check existing datasets. It enabled us at Dataxcel to make informed decisions especially around compliance."
KYC, IDV & Fraud FAQ
What is a KYC data provenance review?
What does "a match is not proof of a person" mean?
What is match plus provenance?
Does breach exposure mean a record is fraudulent?
Can Provero replace my KYC or IDV provider?
Where should identity data be checked?
How can I tell whether a supplier is feeding me breached, recycled or synthetic data?
Can I run these checks by API instead of requesting a review?
What signals does Provero use?
Is the provenance-weighted score available today?
Find out what your data, and your suppliers, are really feeding you
Request a data provenance review and we will examine your records or sources for breach, chronology, phone, location, fraud and synthetic-pattern tells. Prefer to run the signals yourself? Create a free account and call the checks directly.
To request a data provenance review, email support@provero.io